Ransomware attacks surge in July as AI enables faster cyber threats

0
42
Ransomware activity reaches 2026 high as AI reshapes cyber attacks
Ransomware activity reaches 2026 high as AI reshapes cyber attacks

Ransomware activity climbed sharply in July, with 894 attacks recorded, marking a 22% increase from June, according to NCC Group. The cybersecurity company said this was the highest monthly level recorded so far in 2026, although it remained 19% below the record 1,099 attacks reported in February 2025.

A few groups drive most attacks

The Gentlemen was the most active ransomware group in July, accounting for 15% of attacks after incidents rose to 138 from 88 in June. Qilin followed with 127 attacks, up from 79, while Deadlock accounted for 9% of incidents.

Newer group CRPxO claimed 36 victims, around 4% of the total. NCC Group said the claims remain unconfirmed because evidence about the group’s involvement was inconsistent.

North America and Europe remain key targets

North America and Europe together accounted for 70% of ransomware attacks in July, with shares of 41% and 29%, respectively. The industrial sector was the biggest target, representing 28% of all incidents, as attackers continued to focus on organisations with complex operations and large supplier networks.

The report also highlighted the growing role of artificial intelligence in cybercrime. It identified JADEPUFFER as the first known fully autonomous, end-to-end AI-driven agent demonstrated to infiltrate systems and conduct attacks without human instruction.

Such technology could allow attackers to automate more stages of an attack, from initial compromise to extortion, potentially enabling larger campaigns. Early activity appeared focused more on demonstrating autonomous capabilities than immediate financial returns.

NCC Group also examined Operational Relay Box networks, which route cyber activity through compromised devices and infrastructure. These networks can make malicious traffic harder to trace and complicate attribution, particularly in China-linked operations.

Matt Hull, Vice President of Cyber Intelligence and Response at NCC Group, said organisations should continue strengthening basic security measures.

“AI is changing the speed and scale of cyber attacks. It’s allowing attackers to automate more of what they do, operate at greater scale, and create increasingly convincing phishing, social engineering, and other malicious content. That can make threats harder for both organisations and individuals to identify.

“For organisations, the response doesn’t need to be complicated. Getting the fundamentals right remains incredibly important: strong identity and access controls, good vulnerability management, visibility across your environment, and the ability to detect and respond quickly when something goes wrong.

“There’s also a human element. As AI-generated content becomes more convincing, employees need to understand what threats look like, know when something doesn’t feel right, and have a simple way to report it.

“AI is equally valuable for defenders, helping security teams process information faster and identify potentially malicious activity. The challenge is making sure we use that technology effectively while maintaining the human judgement needed to understand what represents a genuine threat.”

Also read: Viksit Workforce for a Viksit Bharat

Do Follow: The Mainstream LinkedIn | The Mainstream Facebook | The Mainstream Youtube | The Mainstream Twitter

About us:

The Mainstream is a premier platform delivering the latest updates and informed perspectives across the technology business and cyber landscape. Built on research-driven, thought leadership and original intellectual property, The Mainstream also curates summits & conferences that convene decision makers to explore how technology reshapes industries and leadership. With a growing presence in India and globally across the Middle East, Africa, ASEAN, the USA, the UK and Australia, The Mainstream carries a vision to bring the latest happenings and insights to 8.2 billion people and to place technology at the centre of conversation for leaders navigating the future.